Compass-Underwriting-Ltd
bd_7307e1ceb9242be9 · schema v1 · pii pii-v1
Full breach record for Compass-Underwriting-Ltd →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Sarcoma on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
compass-underwriting-ltd Our History Originally a Lloyd’s syndicate, Compass has evolved since 1986 to become one of the UK’s leading Accident & Health underwriting agencies and was acquired by the elseco group in April 2022. Accessing a wide range of UK, European, and Lloyd’s markets, Compass provides a full-cycle service to its’ intermediaries and their clients. Our Mission We are dedicated in providing the services needed to help launch accident and health products into your clients’ niche sectors. Compass has a long track record of designing new and innovative products for both start-ups and major players in the UK and European markets. Our Systems Compass operates a comprehensive fulfillment system that seamlessly manages all elements of a sale transaction. From quote to premium collection, plus high-quality MI, you can benefit from our fully hosted toolkit of IT solutions. Cloud hosted, you can access the system from anywhere in the World. Our Status Compass Underwriting is a trading name of Vivet Limited which is a private limited company registered in England (No. 07632781) with a registered address at 35 Ballards Lane, London, England, N3 1XW and is authorised and regulated by the Financial Conduct Authority (FCA Register Firm No. 565079). Vivet Ltd is a member of the Managing General Agents’ Association.Geo: United Kingdom - Leak size: 135 GB Archive - Contains: Files, SQL
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jan 20, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitesarcomabd_a67478b4374d8ce62025-01-20Verified by operator
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
sarcoma
According to ransomware.live, Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally and surpassing 116 documented victims by mid-2025, targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services with roughly 50% of victims in the United States.